✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Telecommunications
Breach intelligence, attack campaigns, and threat reports targeting the Telecommunications sector.
Explore Other Sectors
Telecommunications Threat Reports
Multi-Vector Attacks Surge: DNS Poisoning, Supply-Chain Compromise, and Rust Malware in 2025
In October 2025, a major multi-vector cyberattack was uncovered leveraging DNS poisoning, a sophisticated software supply-chain compromise, and the deployment of a new strain of Rust-based malware capable of evading traditional detection mechanisms. The attackers exploited vulnerabilities in third-party supplier code to infiltrate enterprise networks, enabling lateral movement via compromised DNS servers. Shortly thereafter, remote access trojans (RATs) and other post-exploitation tools were deployed, resulting in significant data exfiltration and disruption across multiple sectors. Incident response teams collaborated internationally to isolate affected systems and assess the operational damage. This event highlights a tightening attacker focus on high-value targets and critical infrastructure, driven by advances in malware tooling, zero-day exploitation, and the mainstream use of modern programming languages like Rust for stealthy payloads. The breach exemplifies how defenders must adapt to increasingly layered threats that combine classic attack vectors with contemporary tactics.
6 months ago
Kill Chain
Critical 2025 Raisecomm Authentication Bypass: Root Access Risk to ICS Networks
In October 2025, a critical remote authentication bypass vulnerability (CVE-2025-11534) was publicly disclosed in Raisecomm RAX701-GC series network equipment, allowing unauthenticated attackers to establish SSH sessions and gain root shell access without providing valid credentials. Discovered and reported by security researchers from runZero, this exploit poses an elevated risk to infrastructure sectors relying on these devices globally, as affected firmware versions remain susceptible with exploits achievable at low complexity and no prior privileges. Business and operational impacts include full remote compromise, lateral movement potential, and the ability for attackers to implant persistent threats or disrupt essential communications and IT operations. The incident is especially pressing now, indicating a rising trend in targeting embedded and edge devices in critical environments via misconfigurations or software flaws. As attackers expand their focus to accessible infrastructure, organizations face increasing pressure to implement robust access controls, proactive segmentation, and defense-in-depth strategies to safeguard operational networks.
6 months ago
Kill Chain
Hitachi Energy TropOS ICS Flaws Threaten Critical Infrastructure Security (2025)
In October 2025, Hitachi Energy disclosed multiple critical vulnerabilities in its TropOS 4th Generation firmware (versions 8.9.6.0 and prior), widely used in critical manufacturing and energy sectors. Three CVEs—CVE-2025-1036, CVE-2025-1037, and CVE-2025-1038—were identified, including OS command injection and improper privilege management flaws in the web-based configuration utility. Exploiting these, authenticated attackers could escalate privileges and obtain root SSH access to affected devices, substantially compromising network security and potentially disrupting critical infrastructure operations. The flaws were reported by Idaho National Laboratory’s CyTRICS program and carry CVSS v4 scores between 7.5 and 8.7. This incident highlights ongoing risks posed by authentication and privilege flaws in industrial control systems (ICS), especially as critical infrastructure devices increasingly attract remote exploitation attempts. It underscores the urgent need for regular firmware updates, network segmentation, and robust access controls amid tightening regulations and persistent adversarial interest in ICS environments.
6 months ago
Kill Chain
Aisuru Botnet’s 2025 Shift: From DDoS Disruptor to Proxy Powerhouse
In mid-2025, the Aisuru botnet—already infamous for record-shattering distributed denial-of-service (DDoS) attacks—shifted tactics, repurposing hundreds of thousands of compromised Internet of Things (IoT) devices to fuel residential proxy networks. Initially detected in August 2024, Aisuru rapidly infected over 700,000 vulnerable routers and cameras, enabling DDoS attacks reaching up to 30 terabits per second. As global internet providers struggled to mitigate these waves, Aisuru’s operators began renting bot-infected devices as residential proxies, granting cybercriminals more effective means to anonymize web scraping, credential stuffing, and data harvesting operations. This incident marks a significant escalation in how botnets are monetized, as botnet-powered residential proxies become a key enabler for content scraping—especially by AI firms seeking vast datasets. The pivot highlights a rising convergence between traditional cybercrime and emerging AI-driven abuse, challenging defenders to address both volumetric attack trends and subtle, persistent data exfiltration.
6 months ago
Kill Chain
AI-Powered Social Engineering Attacks Surge Across Africa in 2024
In early 2024, a surge of AI-powered social engineering attacks swept across Africa, targeting both government agencies and private enterprises. Threat actors utilized AI-generated phishing campaigns, deepfake technology, and sophisticated impersonation tactics to gain unauthorized access to sensitive systems and data. The attackers rapidly evolved their techniques by testing them in diverse African markets, often bypassing conventional security controls using realistic AI-driven lures and voice/video spoofing. The outcome included data breaches, operational interruptions, increased fraud, and reputational harm to affected organizations, while also exposing gaps in detection and response capabilities. This incident highlights the accelerating adoption of AI by cybercriminals, who now leverage machine learning to refine attack vectors and increase success rates. As similar TTPs proliferate globally, organizations face heightened regulatory scrutiny and must rapidly adapt cybersecurity frameworks to counter increasingly intelligent and deceptive threats.
6 months ago
Kill Chain
F5's 2024 Nation-State Breach: Lessons in Supply Chain and Platform Security
In late 2023, F5 Networks experienced a prolonged attack attributed to a nation-state threat actor who gained persistent access to internal systems, stealing segments of BIG-IP source code, undisclosed vulnerabilities, and customer configuration data. The company became aware of the intrusion on August 9, with public disclosure on October 15 following a rare emergency directive from federal authorities. F5 coordinated with security firms and mobilized rapid emergency software and hardware updates across thousands of customer deployments while investigating the breach’s full scope. The identified impact included widespread emergency patching and a limited set of customers affected by stolen configuration data, though F5 reported that most exfiltrated information was not sensitive. This incident underscores ongoing targeting of technology and security vendors by advanced persistent threat actors. With the steady increase in supply chain attacks, the F5 breach highlights the need for stronger product code security, rapid response to vulnerability disclosure, and cross-industry collaboration against sophisticated intrusions.
6 months ago
Kill Chain
Herodotus Trojan Outsmarts Android Defenses with Human-Like Behavior
In October 2025, cybersecurity researchers uncovered a new Android banking trojan, dubbed Herodotus, actively targeting financial institutions and users in Italy and Brazil. The malware stands out by performing sophisticated device takeover (DTO) attacks while mimicking genuine human behavior—specifically attempting to bypass behavioral biometrics and anti-fraud detection. Herodotus infects devices via malicious apps or phishing, granting attackers near-complete control, which they use to exfiltrate sensitive financial and authentication data by simulating legitimate user interaction. The Herodotus incident underscores a troubling advancement in mobile malware—attackers are increasingly leveraging techniques that closely imitate human behavior to elude cutting-edge security controls. This signals a growing risk for banking apps and enterprises relying on behavioral biometrics, and highlights the urgent need for multilayered zero trust strategies and improved east-west visibility in mobile ecosystems.
6 months ago
Kill Chain
LockBit 5.0 Resurgence: How WSUS and F5 Vulnerabilities Fueled 2025's Biggest Ransomware Wave
In October 2025, a coordinated wave of cyberattacks struck major enterprise environments worldwide. Attackers exploited Windows Server Update Services (WSUS) flaws and vulnerabilities in F5 infrastructure, deploying the new LockBit 5.0 ransomware variant. Using phishing, unauthorized RDP access, and advanced persistence techniques, LockBit affiliates moved laterally across networks, encrypting critical data and disrupting cloud-hosted workloads. Compromised systems experienced operational downtime, data theft, and subsequent ransom demands, while threat actor activity on underground forums confirmed an aggressive resurgence and evolving TTPs. This incident underscores the heightened pace and sophistication of ransomware operations, with threat actors exploiting both zero-day vulnerabilities and supply chain channels. As enterprise defenses adapt to increasingly hybrid and distributed infrastructure, recent attacks have spotlighted urgent needs for segmentation, real-time visibility, and policy enforcement to counter proactive adversary tactics.
6 months ago
Kill Chain
How Attackers Are Abusing DNS for Covert Command and Control in 2024
In October 2024, security researchers highlighted a critical technique enabling Command and Control (C2) communication over DNS channels by encoding arbitrary byte values in DNS queries—even when traversing third-party infrastructures like Cloudflare and Google. Using custom-crafted DNS packets, attackers can bypass traffic inspection and filtering, exploiting DNS to exfiltrate or transfer data using modified BASE64 or expanded ASCII, which can evade many traditional network defenses due to protocol limitations and inconsistent validations among DNS providers. This creates a covert path for malware to communicate without detection by standard security tools. This incident underscores a rising trend where attackers leverage ubiquitous protocols—such as DNS—for covert C2, presenting profound challenges for organizations seeking to secure east-west traffic and detect advanced threats. Awareness is crucial, as advanced C2 techniques are increasingly observed in malware campaigns exploiting gaps in DNS monitoring and anomaly detection.
6 months ago
Kill Chain
First Wap's SS7 Exploit: How Altamides Changed Global Surveillance in 2025
In 2025, surveillance-technology firm First Wap, based in Jakarta, was revealed to have quietly built and operated the 'Altamides' system, a covert platform leveraging SS7 telecom vulnerabilities for global phone tracking. Unlike conventional spyware, Altamides enabled real-time location tracking of mobile devices across regions—from the Vatican to Silicon Valley—without requiring user interaction, installation, or leaving traces on targeted phones. The technology exploited legacy telecom protocols to access cell tower information, bypassing most modern mobile security defenses. As a result, sensitive locations and communications were exposed to persistent surveillance risk, with broad geopolitical and privacy implications. This incident underscores a worrying rise in the commercial proliferation of offensive surveillance tools exploiting underprotected telecom infrastructure. It highlights the urgent need for stronger regulatory action and zero trust defenses, as targeted espionage techniques move further away from traditional malware and towards systemic protocol abuse.
6 months ago
Kill Chain
Smishing Triad’s 2024 US SMS Phishing Campaign: Government Impersonation Goes Mainstream
In early 2024, a threat group known as the 'Smishing Triad' launched a wave of phishing attacks targeting American mobile phone users through fake government-related SMS messages. The group impersonated federal and state agencies, primarily sending texts about unpaid toll fees and penalties to lure recipients into clicking malicious links. These links redirected victims to counterfeit payment portals to steal personal and financial information. The campaign used low-frequency, highly targeted smishing tactics which significantly increased trust and subsequent victim engagement, resulting in a notable uptick in credential theft and financial fraud. This incident is part of a broader trend where cybercriminal organizations leverage sophisticated social engineering and government impersonation at a time of regulatory scrutiny around SMS-based phishing (smishing). Its evolving tactics show how attackers adapt to increase impact, highlighting the urgent need for layered, identity- and zero-trust-driven defenses.
6 months ago
Kill Chain
Global Smishing Triad Campaign: 194,000 Malicious Domains Power Massive Phishing Surge
In 2024, security researchers attributed a global smishing campaign to a threat group known as the Smishing Triad, which registered more than 194,000 malicious domains since January 1. Utilizing infrastructure predominantly registered through Hong Kong-based providers with Chinese nameservers, the actors orchestrated widespread phishing via SMS attacks targeting banking, logistics, and other sectors. Victims received highly targeted text messages that redirected them to credential-harvesting sites, leading to financial fraud and data compromise. The campaign’s scale and global reach underline the adversaries’ operational sophistication and heavy use of automation. This incident reflects a broader surge in phishing tactics leveraging SMS and vast domain infrastructure, bypassing traditional email security. The growing adoption of QR and mobile-first communication further widens the threat surface, putting regulatory and compliance emphasis on new vectors.
6 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports